ClickFix campaign abuses Deno runtime for infostealer delivery
Summary
The ClickFix campaign has been observed to leverage the Deno runtime environment to deliver an infostealer. Attackers are utilizing compromised WordPress websites as lures, directing unsuspecting users to download and install the Deno runtime, which then facilitates the deployment of the malicious Python-based infostealer.
IFF Assessment
FOE
This campaign represents a new technique for delivering malware, making it harder for defenders to detect and block.
Defender Context
Defenders should be aware of novel malware delivery techniques like the use of the Deno runtime, as attackers continuously evolve their methods. Monitoring for unusual Deno installations or network traffic associated with it could be a valuable detection strategy.